You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用OpenJDK 14模块化运行时出现TLS 1.3握手失败求助

Hey there, let's break down why your TLS 1.3 connections are failing when using a jlink-built runtime, even though they work perfectly fine with the full JDK/JRE or running the JAR directly.

The Root Cause

When you use jlink, it only packages modules that are explicitly declared in your module-info.java (plus their transitive dependencies). The key issue here is that elliptic curve (EC) cryptography support—critical for most TLS 1.3 handshake workflows—lives in the jdk.crypto.ec module, which isn't included in java.base or your current set of declared dependencies.

Without this module, your custom runtime can't send EC-based supported groups (like ECDHE curves) or ECDSA signature algorithms in the Client Hello. That's exactly what your Wireshark traces showed: only DHE groups and non-EC signature algorithms get sent, which most TLS 1.3 servers won't accept for a successful handshake.

The Simple Fix

  1. Update your module-info.java to add a dependency on jdk.crypto.ec:
    module TlsHostInfo {
        requires java.base;
        requires javafx.controls;
        requires javafx.fxml;
        requires jdk.crypto.ec; // Add this line to include EC cryptography support
        opens certpackage.view to javafx.fxml;
        exports certpackage;
    }
    
  2. Rebuild your jlink runtime with this updated module declaration. The build tool (or jlink itself) will now include the jdk.crypto.ec module in your custom runtime image.

When you run your JAR with the full JDK/JRE, it includes all optional cryptography modules by default. jlink, however, follows a "minimal runtime" philosophy—it only includes what you explicitly ask for. By adding requires jdk.crypto.ec, you're telling jlink to include the EC cryptography components needed for TLS 1.3 to function properly.

Quick Verification

After rebuilding, run your application again and capture a Wireshark trace. You should now see:

  • EC-based supported groups (like x25519, secp256r1) listed in the Client Hello
  • ECDSA signature algorithms (like ecdsa_secp256r1_sha256) included
  • A successful TLS 1.3 handshake with your target server

内容的提问来源于stack exchange,提问作者Cosmopolis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 12:17:39